Debian Linux vulnerabilities

9,914 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,914
CISA KEV
119
actively exploited
Public exploits
429
Exploited in wild
132
Severity breakdown
CRITICAL1128HIGH4113MEDIUM4311LOW362

Vulnerabilities

Page 179 of 496
CVE-2021-23968MEDIUMCVSS 4.3v9.0v10.02021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2021-23969MEDIUMCVSS 4.3v9.0v10.02021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvd
CVE-2020-27618MEDIUMCVSS 5.5v10.02021-02-26
CVE-2020-27618 [MEDIUM] CVE-2020-27618: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing inval The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228
nvd
CVE-2020-27223MEDIUMCVSS 5.3v10.02021-02-26
CVE-2020-27223 [MEDIUM] CWE-407 CVE-2020-27223: In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty hand In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhaust
nvd
CVE-2021-23973MEDIUMCVSS 6.5v9.0v10.02021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2021-20203LOWCVSS 3.2v9.0v10.02021-02-25
CVE-2021-20203 [LOW] CWE-190 CVE-2021-20203: An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2. An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
nvd
CVE-2020-11987HIGHCVSS 8.2v10.02021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2021-27645LOWCVSS 2.5v10.02021-02-24
CVE-2021-27645 [LOW] CWE-415 CVE-2021-27645: The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, wh The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
nvd
CVE-2021-3410HIGHCVSS 7.8v9.02021-02-23
CVE-2021-3410 [HIGH] CWE-119 CVE-2021-3410: A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
nvd
CVE-2021-20247HIGHCVSS 7.4v9.02021-02-23
CVE-2021-20247 [HIGH] CWE-20 CVE-2021-20247: A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IM A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest thre
nvd
CVE-2021-3405MEDIUMCVSS 6.5v9.02021-02-23
CVE-2021-3405 [MEDIUM] CWE-787 CVE-2021-3405: A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlSt A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.
nvd
CVE-2021-3407MEDIUMCVSS 5.5v9.02021-02-23
CVE-2021-3407 [MEDIUM] CWE-415 CVE-2021-3407: A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corr A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
nvd
CVE-2020-27768LOWCVSS 3.3v9.02021-02-23
CVE-2020-27768 [LOW] CWE-190 CVE-2020-27768: In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at Magi In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.
nvd
CVE-2021-26120CRITICALCVSS 9.8v9.0v10.0+1 more2021-02-22
CVE-2021-26120 [CRITICAL] CWE-94 CVE-2021-26120: Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= s Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
nvd
CVE-2021-26119HIGHCVSS 7.5v9.0v10.0+1 more2021-02-22
CVE-2021-26119 [HIGH] CVE-2021-26119: Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sand Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
nvd
CVE-2021-27379HIGHCVSS 7.8v10.02021-02-18
CVE-2021-27379 [HIGH] CVE-2021-27379: An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unin An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DMA access, and possibly cause a denial of service (host OS crash) or gain privileges. This occurs because a backport missed a flush, and thus IOMMU updates were not always correct. NOTE: this issue exists because of an incomplete fix for CVE-
nvd
CVE-2021-26720HIGHCVSS 7.8v9.0v10.02021-02-17
CVE-2021-26720 [HIGH] CWE-59 CVE-2021-26720: avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/net avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE
nvd
CVE-2021-26930HIGHCVSS 7.8v9.02021-02-17
CVE-2021-26930 [HIGH] CVE-2021-26930: An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service request An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, an
nvd
CVE-2020-8625HIGHCVSS 8.1v9.0v10.02021-02-17
CVE-2020-8625 [HIGH] CWE-120 CVE-2020-8625: BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TS BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration option
nvd
CVE-2021-26931MEDIUMCVSS 5.5v9.02021-02-17
CVE-2021-26931 [MEDIUM] CWE-770 CVE-2021-26931: An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn't correct to assume a plain bug. Memory allocations p
nvd
Debian Linux vulnerabilities | cvebase